Skip to content

Commit e7fe321

Browse files
authored
commented out the admission webhook patch (#121)
2 parents 8c4fe3d + f1ede20 commit e7fe321

File tree

1 file changed

+57
-56
lines changed

1 file changed

+57
-56
lines changed

k8s-manifests/cluster-setup/ingress-controller/nginx-ingress.yaml

Lines changed: 57 additions & 56 deletions
Original file line numberDiff line numberDiff line change
@@ -590,62 +590,63 @@ spec:
590590
restartPolicy: OnFailure
591591
serviceAccountName: ingress-nginx-admission
592592
ttlSecondsAfterFinished: 0
593-
---
594-
apiVersion: batch/v1
595-
kind: Job
596-
metadata:
597-
labels:
598-
app.kubernetes.io/component: admission-webhook
599-
app.kubernetes.io/instance: ingress-nginx
600-
app.kubernetes.io/name: ingress-nginx
601-
app.kubernetes.io/part-of: ingress-nginx
602-
app.kubernetes.io/version: 1.13.2
603-
name: ingress-nginx-admission-patch
604-
namespace: ingress-nginx
605-
spec:
606-
template:
607-
metadata:
608-
labels:
609-
app.kubernetes.io/component: admission-webhook
610-
app.kubernetes.io/instance: ingress-nginx
611-
app.kubernetes.io/name: ingress-nginx
612-
app.kubernetes.io/part-of: ingress-nginx
613-
app.kubernetes.io/version: 1.13.2
614-
name: ingress-nginx-admission-patch
615-
spec:
616-
automountServiceAccountToken: true
617-
containers:
618-
- args:
619-
- patch
620-
- --webhook-name=ingress-nginx-admission
621-
- --namespace=$(POD_NAMESPACE)
622-
- --patch-mutating=false
623-
- --secret-name=ingress-nginx-admission
624-
- --patch-failure-policy=Fail
625-
env:
626-
- name: POD_NAMESPACE
627-
valueFrom:
628-
fieldRef:
629-
fieldPath: metadata.namespace
630-
image: registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.6.2@sha256:050a34002d5bb4966849c880c56c91f5320372564245733b33d4b3461b4dbd24
631-
imagePullPolicy: IfNotPresent
632-
name: patch
633-
securityContext:
634-
allowPrivilegeEscalation: false
635-
capabilities:
636-
drop:
637-
- ALL
638-
readOnlyRootFilesystem: true
639-
runAsGroup: 65532
640-
runAsNonRoot: true
641-
runAsUser: 65532
642-
seccompProfile:
643-
type: RuntimeDefault
644-
nodeSelector:
645-
kubernetes.io/os: linux
646-
restartPolicy: OnFailure
647-
serviceAccountName: ingress-nginx-admission
648-
ttlSecondsAfterFinished: 0
593+
### Commented out the admission webhook patch job to prevent errors in lab environments
594+
# ---
595+
# apiVersion: batch/v1
596+
# kind: Job
597+
# metadata:
598+
# labels:
599+
# app.kubernetes.io/component: admission-webhook
600+
# app.kubernetes.io/instance: ingress-nginx
601+
# app.kubernetes.io/name: ingress-nginx
602+
# app.kubernetes.io/part-of: ingress-nginx
603+
# app.kubernetes.io/version: 1.13.2
604+
# name: ingress-nginx-admission-patch
605+
# namespace: ingress-nginx
606+
# spec:
607+
# template:
608+
# metadata:
609+
# labels:
610+
# app.kubernetes.io/component: admission-webhook
611+
# app.kubernetes.io/instance: ingress-nginx
612+
# app.kubernetes.io/name: ingress-nginx
613+
# app.kubernetes.io/part-of: ingress-nginx
614+
# app.kubernetes.io/version: 1.13.2
615+
# name: ingress-nginx-admission-patch
616+
# spec:
617+
# automountServiceAccountToken: true
618+
# containers:
619+
# - args:
620+
# - patch
621+
# - --webhook-name=ingress-nginx-admission
622+
# - --namespace=$(POD_NAMESPACE)
623+
# - --patch-mutating=false
624+
# - --secret-name=ingress-nginx-admission
625+
# - --patch-failure-policy=Fail
626+
# env:
627+
# - name: POD_NAMESPACE
628+
# valueFrom:
629+
# fieldRef:
630+
# fieldPath: metadata.namespace
631+
# image: registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.6.2@sha256:050a34002d5bb4966849c880c56c91f5320372564245733b33d4b3461b4dbd24
632+
# imagePullPolicy: IfNotPresent
633+
# name: patch
634+
# securityContext:
635+
# allowPrivilegeEscalation: false
636+
# capabilities:
637+
# drop:
638+
# - ALL
639+
# readOnlyRootFilesystem: true
640+
# runAsGroup: 65532
641+
# runAsNonRoot: true
642+
# runAsUser: 65532
643+
# seccompProfile:
644+
# type: RuntimeDefault
645+
# nodeSelector:
646+
# kubernetes.io/os: linux
647+
# restartPolicy: OnFailure
648+
# serviceAccountName: ingress-nginx-admission
649+
# ttlSecondsAfterFinished: 0
649650
---
650651
apiVersion: networking.k8s.io/v1
651652
kind: IngressClass

0 commit comments

Comments
 (0)